The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2022-02-28 09:15
Updated : 2022-02-28 13:38
NVD link : CVE-2021-24823
Mitre link : CVE-2021-24823
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
